Skip to main content
SeentrixSeentrix
EU Cyber Resilience Act

CRA compliance,
handled.

Seentrix turns the Cyber Resilience Act into a clear, trackable workflow — scoring every product, managing vulnerabilities, and drafting the documents you need to ship in the EU.

Get started

Time until CRA reporting obligations

00Days
:
00Hours
:
00Minutes
:
00Seconds

The CRA Compliance Challenge

Manufacturers face unprecedented cybersecurity obligations under the EU Cyber Resilience Act.

66%of those surveyed are still unfamiliar with the CRA

Not familiar at all or only slightly familiar with the regulation — Linux Foundation / OpenSSF research, 2026.

24hvulnerability reporting deadline

Actively exploited vulnerabilities must be reported to the designated CSIRT and ENISA within 24 hours.

€15Mmaximum penalty for non-compliance

Or 2.5% of worldwide annual turnover, whichever is higher.

Everything the CRA asks for, in one place

From first risk assessment to CE marking — Seentrix keeps your whole portfolio audit-ready.

Conformity scoring

A live readiness score for every product, mapped to the CRA's essential requirements — so you always know what's left.

Vulnerability handling

Track CVEs by CVSS, manage coordinated disclosure, and meet the 24-hour ENISA reporting duty without scrambling.

Documents, drafted

Generate SBOMs, risk assessments and the EU Declaration of Conformity — assembled from your data, ready to sign.

AI Copilot

Ask what's blocking conformity, triage incidents, or have a compliance document drafted in seconds.

Deadline tracking

Every CRA milestone on one calendar, with reminders that escalate as dates approach.

Academy

Get your whole team CRA-fluent with short, practical courses built for product and security people.

Seentrix AI

A CRA assistant built entirely on European infrastructure.

A CRA-specialist assistant built into Seentrix. Ask questions in plain English and get answers grounded in the regulation itself — on infrastructure hosted end-to-end in Europe.

01

European by design

Powered by Mistral AI in Paris. Every hop in the pipeline runs on European infrastructure.

02

Grounded in the regulation

Every answer cites the specific article, annex, or Seentrix page it was drawn from.

03

Context-aware

Knows which screen, product, and organisation you're looking at. Replaces "where's that feature again?".

04

Actionable

Deep-links to the right page, drafts incident narratives on request, and explains what's missing before you issue a DoC.

Get Compliant in 3 Steps

From first assessment to audit-ready documentation — Seentrix guides you through the entire CRA compliance journey.

1

Assess Your Products

Run the scope assessment to determine your CRA category, conformity route, and whether a notified body is required.

2

Track Requirements

Work through interactive checklists mapped to CRA Annex I. Upload your SBOM and scan for known vulnerabilities.

3

Generate Documentation

Export your EU Declaration of Conformity, technical documentation, and vulnerability handling policies — ready for auditors.

Built for Product Manufacturers

We built Seentrix so manufacturers of every kind can navigate CRA compliance with confidence, from first assessment to market-ready documentation.

01

Industrial & OT

Map your PLCs, SCADA systems, and industrial controllers against CRA Annex I requirements. Get clarity on conformity routes and notified body obligations for your operational technology.

02

IoT Devices

Manage cybersecurity-by-design obligations for connected consumer and commercial devices. Track vulnerabilities, maintain SBOMs, and generate the documentation auditors expect.

03

Software & Firmware

Assess standalone software products and embedded firmware against CRA scope criteria. Automate vulnerability monitoring and produce EU Declarations of Conformity from templates.

Built by Compliance Engineers

Built in the United Kingdom by a team with deep roots in industrial automation and cybersecurity standards.

Your data is hosted in Europe. Database + file storage on Supabase in London (eu-west-2, UK — adequacy decision), web application on Vercel in Frankfurt (fra1), error tracking on Sentry in Germany (de.sentry.io). Providers outside the EEA (payments, email) operate under Standard Contractual Clauses — see the DPA.

IEC 62443
ETSI EN 303 645
GDPR Compliant
European data residency

Simple, Transparent Pricing

Start free and upgrade as your compliance needs grow. See the full comparison table on the pricing page.

Free

Explore CRA requirements

€0
  • 1 product · 1 user
  • Full compliance checklist
  • Academy + glossary
Get Started
Most Popular

Professional

Solo founders, 1–3 products

€59/mo
  • 3 products · 3 users
  • SBOM + vulnerability scanning
  • DoC + end-user info PDFs
  • Incident reporting (Art. 14)
Get Started

Business

Compliance teams, multiple products

€219/mo
  • 15 products · 10 users
  • Daily continuous monitoring
  • Public PSIRT + security.txt
  • API access · Priority support
Get Started

Need more than Business?

Large portfolios, SSO, custom SLA — we'll tailor a plan to you.

Get in touch
Compare all 60+ features

Full feature matrix across every tier, including upcoming additions.

CRA Timeline

Three deadlines stand between you and the EU market

The Cyber Resilience Act rolls out in phases. Miss one and your product can't ship to the EU.

  1. June 2026

    Notified Bodies

  2. September 11, 2026

    Vulnerability Reporting

  3. December 2027

    Full CRA Enforcement

Not sure which requirements hit your product?

Classify your product — free

Dates pulled from Regulation (EU) 2024/2847. Verify against the official text on EUR-Lex before relying on them in legal filings.

Frequently Asked Questions

Everything you need to know about the CRA and how Seentrix helps.

The CRA is an EU regulation that establishes mandatory cybersecurity requirements for all products with digital elements sold in the European market. It covers hardware and software, from IoT devices to industrial controllers.

If you manufacture or import products with digital elements into the EU market, the CRA likely applies. This includes connected devices, standalone software, and embedded firmware. Run our free scope assessment to find out in minutes.

The CRA entered into force in December 2024 and applies in stages: notified body provisions from June 11, 2026, reporting of actively exploited vulnerabilities and severe incidents from September 11, 2026, and full application from December 11, 2027.

Non-compliance can result in fines up to €15 million or 2.5% of worldwide annual turnover, whichever is higher. Products can also be withdrawn from the EU market.

You can complete your first scope assessment in under 10 minutes. Most teams have a full compliance picture within a few days, depending on the number of products and complexity.

Yes. The free plan includes one product with basic scope assessment and a read-only compliance checklist. No credit card required.

Get Your Free CRA Readiness Checklist

Join our newsletter and receive a practical checklist to assess your CRA readiness, delivered straight to your inbox.

Security check

We respect your privacy. Unsubscribe at any time.